Multiple vulnerabilities have been discovered in KDE Libraries, the worst of which could lead to man-in-the-middle attacks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201406-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: KDE Libraries: Multiple vulnerabilities Date: June 29, 2014 Bugs: #358025, #384227, #469140, #513726 ID: 201406-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in KDE Libraries, the worst of which could lead to man-in-the-middle attacks. Background ========= KDE is a feature-rich graphical desktop environment for Linux and Unix-like operating systems. KDE Libraries contains libraries needed by all KDE applications. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdelibs < 4.12.5-r1 > = 4.12.5-r1 Description ========== Multiple vulnerabilities have been discovered in KDE Libraries. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could cause a man-in-the-middle attack via any certificate issued by a legitimate certification authority. Furthermore, a local attacker may gain knowledge of user passwords through an information leak. Workaround ========= There is no known workaround at this time. Resolution ========= All KDE users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kdelibs-4.12.5-r1" References ========= [ 1 ] CVE-2011-1094 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1094 [ 2 ] CVE-2011-3365 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3365 [ 3 ] CVE-2013-2074 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2074 [ 4 ] CVE-2014-3494 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3494 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201406-34 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
KDE 3.4.2 update. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-675 2005-07-29 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdelibs Version : 3.4.2 Release : 0.fc4.1 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment. KDE Libraries include: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). ---------------------------------------------------------------------Update Information: KDE 3.4.2 update ---------------------------------------------------------------------* Tue Jul 26 2005 Than Ngo 6:3.4.2-0.fc4.1 - update to 3.4.2 ---------------------------------------------------------------------This update can be downloaded from: 5c63bc29066bd908fac5c1a05d13283f SRPMS/kdelibs-3.4.2-0.fc4.1.src.rpm 1a8b6d3bb202a87386770b675a68f46e ppc/kdelibs-3.4.2-0.fc4.1.ppc.rpm c5bb72aa9d26ff1dcfbffe3eff3b3aa4 ppc/kdelibs-devel-3.4.2-0.fc4.1.ppc.rpm 4ae1c1513208475967f0a95497cb8af8 ppc/debug/kdelibs-debuginfo-3.4.2-0.fc4.1.ppc.rpm 3d442ac2b3a3338b27f0efd5b0915ec0 ppc/kdelibs-3.4.2-0.fc4.1.ppc64.rpm 37a83e7f99b7578830d78b2407fc7362 x86_64/kdelibs-3.4.2-0.fc4.1.x86_64.rpm edac98e4b390c9a19a9a800647253c02 x86_64/kdelibs-devel-3.4.2-0.fc4.1.x86_64.rpm 57529177db5327cb3d8e3c4746e8a58d x86_64/debug/kdelibs-debuginfo-3.4.2-0.fc4.1.x86_64.rpm 63f090cbf9f5cd82d45592216d3a1334 x86_64/kdelibs-3.4.2-0.fc4.1.i386.rpm 63f090cbf9f5cd82d45592216d3a1334 i386/kdelibs-3.4.2-0.fc4.1.i386.rpm 6911f6903492ac75a24264890795feee i386/kdelibs-devel-3.4.2-0.fc4.1.i386.rpm d7c8d77f849a591e9bd987ca5807ffcc i386/debug/kdelibs-debuginfo-3.4.2-0.fc4.1.i386.rpm This update can also be installed with theUpdate Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.